Vulnerability Description
foreman before version 1.15.0 is vulnerable to an information leak through organizations and locations feature. When a user is assigned _no_ organizations/locations, they are able to view all resources instead of none (mirroring an administrator's view). The user's actions are still limited by their assigned permissions, e.g. to control viewing, editing and deletion.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Theforeman | Foreman | 1.15.0 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/96385Third Party AdvisoryVDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-7078Issue TrackingThird Party Advisory
- https://github.com/theforeman/foreman/commit/5f606e11cf39719bf62f8b1f3396861b323Third Party Advisory
- https://projects.theforeman.org/issues/16982Vendor Advisory
- https://seclists.org/oss-sec/2017/q1/470Mailing ListThird Party Advisory
- https://theforeman.org/security.html#2016-7078Vendor Advisory
- http://www.securityfocus.com/bid/96385Third Party AdvisoryVDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-7078Issue TrackingThird Party Advisory
- https://github.com/theforeman/foreman/commit/5f606e11cf39719bf62f8b1f3396861b323Third Party Advisory
- https://projects.theforeman.org/issues/16982Vendor Advisory
- https://seclists.org/oss-sec/2017/q1/470Mailing ListThird Party Advisory
- https://theforeman.org/security.html#2016-7078Vendor Advisory
FAQ
What is CVE-2016-7078?
CVE-2016-7078 is a vulnerability with a CVSS score of 4.3 (MEDIUM). foreman before version 1.15.0 is vulnerable to an information leak through organizations and locations feature. When a user is assigned _no_ organizations/locations, they are able to view all resource...
How severe is CVE-2016-7078?
CVE-2016-7078 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-7078?
Check the references section above for vendor advisories and patch information. Affected products include: Theforeman Foreman.